[saag] Re: [nasr] Re: Re: NASR BOF Follow-Up
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Eric Rescorla <[email protected]> wrote: > However, it's not clear to me that that's true in this case, because > unlike media players, network devices are highly configurable and a > large number of the configuration directives might impact the relevant > security claims. Thus, determining whether an element is policy > conformant is a matter of knowing not just what code it is running > but the state of every relevant configuration directive. One could > imagine this working at least three ways: I think you are making routers sound way more complicated than they are. 1. 90% of directives have little to no affect. (I have one toe in the routing/operations space. I'm ASN26227) 2. they are significantly less complicated than Windows, yet all that media based DRM stuff you mentioned is dependant upon windows boot doing the right thing. 3. the routers in question are usually controlled almost entirely via SDN/YANG. As such, there are *significantly* fewer variations in configuration than there used to be. Yes, you can probably get JUNOS (which is a FreeBSD kernel) to run a minecraft server. And they even have enough RAM to do so. But, that's not a configuration that we would expect. 80% of "is valid configuration" probably amounts to: are there any mirror ports enabled? > In the former case, it is quite likely that there will be a large > number of valid states, because each directive may have multiple > acceptable values, and so you end up with combinatoric explosion > issues if you just have a list of hashes [0]. In the latter case we yet, the *routing* people with the expertise here, and a few operators seem pretty sure they can do this. > Either approach requires studying the impact of every existing > configuration directive for each device type to know what the > impact will be on the relevant policy claims. This seems challenging > at best. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmfy2OcWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZYToCACn+8nIVpOkDO07X3WiKtWx/ztd zz2hIUPSDK+ITJhT2dgQi/zbN8VAAiru7eN0rl1c3oAiQC30ddX0czUUZwdg/159 KcMcXfEkso/kzi9df3IKKPiq/cHm5EvySGQVCwvkNfp7XvwTI2J2lKZT9nGpYKla WVyfUpw6NXNSdS8g5stcz4k+GasrsCO+Y7LpZtrprbOHN28+7UN4jTKGjMR+BR8q mN7Bd9QAxeXNqQV+Kbh6v9pupwAMLpWNmpUi3NaJThOPiIhGbBlfMHV0pDHzEfaH +Ws/dsazMS5rrzzPECdTL06e8li0qZlUtvMq1GlenZ+/9NkqUvK9hNuJhp9P =a5vK -----END PGP SIGNATURE-----